Seven sections from 30 single-function opus workflows on 187-297 instruction targets (30/30 MATCH):
§339 a 2-case switch OMITS gcc's low-bound range test (stmt.c emit_case_nodes) — so slti/bnez
between two beqs is a COUNT TELL that a case node is missing from your draft
§340 §194-K corollary: a 'scheduler' residual can be sched.c's ALIAS ORACLE inventing a false
true-dependence; source order picks the edge's DIRECTION, so reverse it into an anti-dep
rather than fighting it (10->0, zero bytes; 3 alternatives refuted with reasons)
§341 an HImode store temp reweights a sched2 tie no statement order can reach
§342 NEW LAW: a twin's param cast in a local is NOT byte-neutral when a later param also
needs a callee-saved reg — and the §333 converse does NOT hold (gcc may already pad the gap)
§343 decl_prior's fleet MAJORITY can be wrong about the true signature — read the RIVALS.
Measured: void(s32) x1374 vs the truth s32(s32) x163. The tool is honest, the corpus is wrong.
§344 raise a biv's global_alloc priority with a zero-byte REFERENCE; a register pin kills LSR
§345 volatile STORE evicts the MEM from cse and keeps sh; volatile LOAD blocks combine and
degrades lh into lhu+sll+sra — the qualifier is not symmetric
Also: seed_ref validated on a live A/B. The same 187-ins body cost 102,193 tokens / 476 s in
ov_SC03_107 when the card said 'no banked twin', and 72,077 tokens / 135 s in ov_SC07_006 once the
card carried the twin — 30% fewer tokens, 3.5x faster. A second instance (func_8017F62C) went
63,595 vs 118,485 tokens. others_open=137 on that one exemplar, so it compounds.
Measured a SECOND time in S67, and the first fix was incomplete. A waiter using the bracketed
pattern still matched itself and spun 1h35m, because the same shell command had LAUNCHED the job —
so its own command line carried the unbracketed 'gate_stage.py --binary ov_SC07_007' from the nohup
half. The regex gate_[s]tage.py does not match the literal bracketed text, but it happily matches
the plain text sitting earlier on the same line.
Rule is now: launch and wait in SEPARATE shell invocations, or better, wait on a completion MARKER
the job writes to its own log rather than on process liveness.
THE DOC GAP, and it cost tokens this session. `docs/automation-runbook.md` was titled "the
autonomous campaign, as it actually runs" while documenting the RETIRED OpenRouter/ox-alpha system
whose lanes are all deliberately DEAD. The current Claude-wave pipeline existed only as two dense
tooling-inventory rows in SETUP.md — reference, not procedure. Three of this session's costliest
mistakes were procedural and a playbook prevents each:
* hand-typed a refill target -> invented func_80184F60 (2nd instruction of a matched function), 58k
* hand-rolled a serial gate loop when parallel_gate existed -> ~1h for what took 103s
* re-derived a function banked verbatim in ~20 overlays -> 102k
NEW docs/wave-playbook.md — start to finish, each guard paired with the MEASUREMENT that produced it
(that pairing is the part a generic decomp guide cannot have, and the seed of the future template).
automation-runbook.md retitled HISTORICAL with a pointer; SETUP.md §6.9 links the playbook.
NEW tools/seed_ref.py — the cross-TU banked twin, joined on corpus signature hashes (no atlas knn,
~2s fleet-wide), wired into t5_cards.py. FLEET: 87 open stubs have a banked twin; 41 of them sit in
twin_sweep's refusal ledger, invisible to BOTH tools at once. Documents twin_sweep's two holes:
load_sigs covers 141/213 binaries (main, resident, all md_MAIN_* absent), and one curated symbol
name silently disables an entire binary via a bare `except Exception: pass`.
Schema note: seed_ref's binary/fn are the EXEMPLAR's, because api_agent greps src/{binary} for {fn};
naming them after the target would send every agent grepping for itself — caught pre-ship.
HARVEST §333-§338 from the s67o2_1/pool_1 waves:
§333 frame size is set by DECLARED aggregates, not used ones — an unreferenced trailing local is a
dial (3 instances; one worth 30 of 32 residual rows)
§334 a reload spill slot rounds to BIGGEST_ALIGNMENT for align AND size: one 4-byte pseudo grew a
frame by 16 (82->53)
§335 `extern u16 A[]` at a variable subscript allocates ~8B/access of dead stack temps that inflate
the frame with ZERO extra instructions — invisible in a body diff (141->20)
§336 the §5a barrier goes at the BOTTOM of the twin; find_cross_jump walks BACKWARD
§337 the CC1-ONLY blocker class: blocker_probe's static oracle says "none" and cc1 still fails
§338 _sltiu_bounds misreads a non-switch sltiu as a bounds check, over-spanning the table
gate_wave.py now STREAMS both lanes (R55) — it captured output and printed at the end, leaving a
zero-byte log indistinguishable from a hang.
Wave s67m2_1: 7 sonnet agents, 1 MATCH banked, 6 NEAR — but 4 of the 7 are NOT drafting failures:
* func_8005FA94 / func_8005D244 — oracle_reorder.py bypass gives 0/55 and 0/62 diffs: the C is
byte-correct, the pinned as -O1 cannot emit the §188 epilogue. func_8005D244 is additionally
libpad pdent3.o, an SDK object owned by psyq_integrate.py — it should never have been drawn.
* func_80062144 / func_8005DBD8 — §332, traced to the compiler sources: gcc-2.7.2 emits a symbolic
la as ONE atomic length-2 insn (no HIGH/LO_SUM split in this backend), eligible_for_delay requires
length==1, so it can never fill a jump delay slot; the retail split is ASPSX macro-hopping that
maspsx does not replicate. Byte-verified by running maspsx over cc1's raw -dS output.
6 such functions fleet-wide, NONE banked.
§332a records the draw-policy consequence: main's cheap population is spent and the residual is
ENRICHED in toolchain walls, so main's apparent match rate is contamination, not a model signal.
Wall ledger at .run/S67_walls.txt for the --exclude mechanism.
HARVEST — the s67o1/s67m1 wave banked 7 cookbook sections:
* §325 a shared small constant stored twice in the pre-loop block is a LOCAL-ALLOC $s-occupant that
steals the argument allocno's register — pin the ARGUMENT-derived local, not the constant
(pinning the constant reached only closeness 15). byte-proven func_80184F18.
* §326 spelling two reads of the same halfword differently (sym[i] vs *(s16*)(base+i*4+2)) yields
different address rtx and DEFEATS address-CSE, restoring separate %hi/%lo groups. func_8017FAAC.
* §327 a range test must be HImode: with s32 + a (u16) cast gcc PROVES the mask redundant and drops
the andi — a real -1 length drift that reads as a schedule. +3 levers. func_8017EC34.
* §328 NEW LAW: the volatile alias must be an aliased OBJECT; `*(volatile s32*)&sym` unfolds %lo
into a separate addiu (+1 ins). func_80181B8C.
* §329 fold-const narrows `(int)s16 & 0xFFF` onto the RAW HImode pseudo, breaking the
sign-extend/mask register tie; a zero-byte `s32 e = t;` widening temp restores it (30 rows -> 0).
* §330 the NEIGHBOUR-SHAPE lever, four independent instances in one wave — copy an already-banked
in-TU function's SPELLING before any codegen reasoning (one dissolved 18 REGALLOC-PERM rows in a
single compile). Corollary: a warm start from another binary is often worth LESS than the
neighbour 20 lines away.
* §331 OPEN GAP, recorded as unsolved: no lever eliminates an UNWANTED DUPLICATE copy at a
branch-target block head (main/func_80013154, closeness 12, ~16 iterations, 5 approaches refuted).
TOOLIFY — tools/gate_wave.py: split the batch on the per-draft jtbl predicate, run parallel_gate
and the serial jtbl lane CONCURRENTLY. Measured this session: 4 binaries in 103s wall through
parallel_gate (87/87/88/102s each) vs ~6 min serially; I had gated all 16 serially to protect ONE
jtbl draft, ~1 hour. The split precedes the run because a jtbl worker does NOT fail cleanly — it
re-extracts through the worktree's asm/ symlink and writes the MAIN tree while other workers read it.
Its own negative control found two defects in it before first use:
* listdir counted gate_stage's _xform output dirs (-cn/-cast/-rc/-sd, written as SIBLINGS inside
the drafts root) as binaries: 20 "binaries" for a 16-binary wave. Now validated against
progress.BINARIES and refused loudly (R32/R43).
* a post-hoc control over BANKED functions cannot reproduce a split (has_jtbl has no stub to read);
re-controlled against a live draft set, where it correctly routes the two functions the gate had
independently reported CARVE-REFUSED.
Wave s67m1: 7 sonnet agents, 0 errors. 5 MATCH banked after bisection in 9 rebuilds;
the 2 NEAR drafts rejected exactly as their agents predicted (func_80013154 close=12,
func_8005ECC0 close=6).
One draft's declaration refused the whole batch first: func_8002A088 declared
`extern s32 func_8002A108(void);` while src/800.c DEFINES it as (s32) at line 15270.
Fixed with the no-proto half of cookbook §324 (`extern s32 func_8002A108();`) — a
no-prototype decl is compatible with a promotion-safe definition and leaves the 0-arg
call unchecked, byte-neutral for the emitted jal. Argues for wiring §324 into the ladder
rather than hand-applying it; it cost a full main gate cycle.
NOTE for the ledger: func_8005E8E8 and func_8005EC00 are verbatim file-scope __asm__
transcriptions, not decompiled C — both hit the §188 wall (2 callee-saved regs with
jr $ra + addiu $sp in the delay slot, unreachable from cc1 under the pinned as -O1),
and both follow established in-TU precedent (func_8005E79C, func_8005EB28).
WALL LEDGER candidates: func_8005ECC0's epilogue tail is proven unreachable via
oracle_reorder.py; only idx24-26 (a beq delay-slot steal) remains open there, and it has
now resisted 8 prior wave attempts plus 3 today.
R22 caught it: 212/213 after the S67-cc1 gate run. `ov_SC04_018` was RED.
ROOT CAUSE (from the diff, not inferred). Commit commit:3354's propagation replaced three bodies in
`ov_SC04_018_jr_80135D20.c` with DEFINE_func_*() instantiations and deleted the 981 lines they
occupied — INCLUDING the TU's file-scope declaration layer, which the two surviving non-deduped
bodies still referenced. A duplicate copy of those decls survived at line 225, BELOW the function
that uses them at line 42, so C89 ordering made it fatal (`D_8018D7A4' undeclared).
THE STRUCTURAL GAP: gate_stage byte-gates the SOURCE binary, then propagation writes to N OTHER
binaries and nothing re-verifies them. "fleet 99.2%" in the commit subject is a metric, not a gate.
This is the blind spot R50 exists for, and only the periodic whole-fleet R22 could see it.
REPAIR: restored src/ov_SC04_018 to commit:3354^, re-extracted (banking had pruned the .s stubs the
restored INCLUDE_ASM lines need), rebuilt rc=0 at the locked SHA fe9b413f. dedup-check clean
(2193 validated, 0 failed, C1 255302/255302). Cost: the 2 banks in that binary.
NEW tools/restore_dropped_decls.py — compiler-driven recovery for this failure mode: build, read
which identifiers cc1 calls undeclared, look each one up in the pre-deletion git ref, insert it
above the leading #include block, repeat. Two defects found and fixed in it while using it:
* anchoring after "the last extern in the first 400 lines" inserts BELOW the point of use, so the
build fails identically and the loop re-inserts forever (measured: 25 rounds, 100 dead decls).
The only safe anchor is the top of the file.
* a no-progress guard now REFUSES when a round asks for what the last round already inserted.
It also correctly refused when the failure changed class (link-level undefined references), which
is how the wider damage was found rather than papered over.
NOT a defect of the S67 §8d rung: scope_demote_drafts only ever writes draft dirs under .run/.
FLEET: make clean + extract-all + check-all = 213 passed, 0 failed of 213.
FRONTIER: 530 -> 526 (4 functions closed this session, measured from corpus.stubs).
MEASURED (denominators in .run/S67_findings.md):
* 193 of the 530 open functions ALREADY have a draft on disk (1,885 wave targets seen,
1,521 banked, 171 open-no-draft, 166 never drawn). Classified in their real TUs:
37 MATCH / 67 NEAR / 89 CC1-FAIL.
* 159 open functions (30% of the frontier) reference a jump table; 96 are PLAN-REFUSED
by build_carve (non-contiguous same-subseg .rodata), 75 non-main across 38 subsegs.
Not a codegen wall and not a decl wall — carve plumbing.
NEW
* tools/strand_census.py — coverage-asserted census + rtu_match classifier + draft staging.
Keys binary:fn (R48); classifies each pair once after merging every manifest's view.
* tools/o0_detect.py — the -O0 prologue tell extracted from match_one (which parses argv at
import and therefore cannot be imported). match_one re-exports it; ONE definition (R33).
Wiring it into the classifier turned md_MAIN_003 from 8 NEAR (7 of them >20) into 6 MATCH.
Negative-controlled both directions.
* tools/scope_demote_drafts.py — §8d as an _xform-contract gate rung. NOT yet exercised.
FIXED
* jtbl_carve --probe now runs build_carve (a pure planner) and reports plan-refused. It
previously called only island_probe, which answers a necessary-not-sufficient question —
every blocked function probed "carveable", and S66 priced 32 of them as free on that.
* blocker_probe.macro_scope selects the LAST #define per macro name, matching cpp.
engine_core.h has 1,037 duplicate DEFINE_func_ names and 4 with DIFFERENT bodies.
NOT VALIDATED — DO NOT SCALE
* jr_isolate_all: two real defects fixed (carried types deduped by name; header-provided
types no longer re-emitted) but ov_SC02_000 STILL fails the byte gate after them.
Open lead: file_scope_types carries a block without its enclosing #if guard. 20 of 35
blocked overlays dry-run clean and that number means nothing until one round-trips.
0 functions banked this session. tools-health has ONE pre-existing cdecl defect
(1 of 74,749 declarations, func_8017EE08_p55352/struct ZnRec) — cdecl.py and its inputs
are byte-identical to HEAD, so it is not from this change.
Knowledge banked: cookbook §322/§323/§323a/§323b, decision-log pivot, accelerators #13/#14.
Written after the last harvest, per the rule that the checkpoint is always last. Supersedes the
interim S66 block. Machine quiesced, tree clean at commit:3350.
Leads with the three things a fresh session must not re-learn: main is ~94 open not 1,099 (and
drafting into a LINKED subseg would gate GREEN while wrong); the family era is over so integration
is the whole game (147 of 591 open fns already had byte-correct drafts stranded on four blockers);
and 'independent' means a different INSTRUMENT — two refusals from parallel_gate were one instrument
twice, after which the serial gate banked 16/32 of that class.
Also records that ~56 of the 416 banks came from ZERO drafting agents, purely from work already on
disk, and Drew's binding harvest-then-toolify-before-the-next-wave rule.
draw_waves.py gains --only-main (the main lane draws main and nothing else; implies --main so the
LINKED refusal still applies). Progress/backlog regenerated: fleet 99.2% instruction-weighted,
98.1% distinct.
From the two cast-at-use reconcile lanes (27 agents on drafts the gate DROPPED for in-TU decl
conflicts, not codegen). 24 reconciled to MATCH, 19 banked.
§320 — §43 and §183 item 4 both record the return-type flip pair (TU says void, body materializes
$v0 on every exit) as TU-EDIT-REQUIRED IMMOVABLE. It is not: three agents broke it three ways in a
single lane, each byte-proven.
1. §202 asm-label alias — s32 aF800CCBC0(void) __asm__("func_800CCBC0") — TU untouched
(func_800CCBC0 138/138 first try; func_800D30D0 76/76).
2. register $2 + input-only asm barrier before a bare return, with the early exit routed through
a goto to a SHARED label — measured bound: inline in the if body is NEAR closeness 10, shared
exit is MATCH (func_800D2A24).
3. Adopt the TU's own old-style K&R decl rather than writing a prototype (func_800CB1CC 47/47).
Plus: when every caller discards the result a TU void->s32 widening IS byte-neutral, but MEASURE it
(null-draft rebuild must still give 143dbb89…) — done twice here. And the process trap that cost a
pass: gate_main snapshots and RESTORES the TU between passes, so an uncommitted TU edit is reverted
before the gate sees it.
§321 — two anonymous struct typedefs are distinct types to gcc-2.7.2 even when spelled identically,
so a file-scope duplicate is fatal while the SAME TEXT at block scope is only a warning and is
codegen-neutral. Three dials, all byte-proven: demote to block scope; or hoist and delete the local
copy; or name a local typedef for its OWN address (SVEC_8017E07C, not a neighbour's SVEC_8017E158).
Not a cast-at-use case — the conflict is type IDENTITY, not width.
src/800.c declares func_8002A544/func_8002A2D4/func_8002A7B4 as `extern void f(s32)`, but each
body genuinely materializes a value in $v0 on both exits (asm-proven). Under a true void signature
gcc-2.7.2 dead-codes exactly those materializations, so the byte-correct s32 body can never compile
in this TU — cookbook §43's 'return-type flip pair', which §183 records as TU-edit-required.
All three call sites discard the result (`func_8002A544(0x32);` as a bare statement), so widening
the declaration cannot change a caller. NEGATIVE CONTROL, run twice: with the edit applied and NO
draft substituted, main still builds 143dbb89f34491258bbc27810d0a12ec8b43a8dd, identical to
config/check.us.sha. The edit is byte-neutral by measurement, not by argument.
Committing it SEPARATELY because gate_main snapshots and restores the TU between passes: an
uncommitted edit is reverted before the gate ever sees it (measured — the first attempt banked 4 of
7 and left all three of these as stubs).
Note for the record: the S66 overlay reconcile lane proved this class also has DRAFT-ONLY escapes
that need no TU edit at all — §202's asm-label alias (`s32 aF800CCBC0(void) __asm__("func_800CCBC0")`,
used byte-proven on func_800CCBC0 and func_800D30D0) and a new register-$2 + input-barrier + shared
goto-exit lever (func_800D2A24). Those are the smaller blast radius and should be preferred where
the TU is shared; this edit is kept because it is proven neutral and these three drafts already
exist in s32 form.
Written for a fresh session. Headlines: main is ~100 open not 1,099 (960 stubs are LINKED dead text,
and drafting into them would gate GREEN while wrong); families are spent (84-93% singletons, twin
pool dry); integration is now the whole game (147 of 591 open fns already had byte-correct drafts
stranded on four blockers). Records Drew's binding rule — harvest, then toolify, BEFORE the next
wave — and the F18 retraction: two refusals from parallel_gate were one instrument twice, not two
independent tests; the serial gate then banked 16/32 of that class.